|
551
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-42986
|
2026-06-12 01:02 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
552
|
8.1 |
HIGH
Network
|
microsoft
|
windows_server_2012 windows_server_2016 windows_server_2019 windows_server_2022 windows_server_2025
|
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
New
|
CWE-416
Use After Free
|
CVE-2026-42987
|
2026-06-12 00:46 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
553
|
7.5 |
HIGH
Network
|
vmware
|
spring_framework
|
Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the followi…
New
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2026-41848
|
2026-06-12 00:45 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
554
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
New
|
CWE-59
Link Following
|
CVE-2026-42989
|
2026-06-12 00:45 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
555
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
New
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-42991
|
2026-06-12 00:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
556
|
5.3 |
MEDIUM
Network
|
vmware
|
spring_framework
|
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker t…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-41852
|
2026-06-12 00:43 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
557
|
7.5 |
HIGH
Network
|
-
|
-
|
TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process b…
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-42542
|
2026-06-12 00:37 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
558
|
7.5 |
HIGH
Network
|
-
|
-
|
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processi…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-5497
|
2026-06-12 00:37 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
559
|
8.4 |
HIGH
Local
|
microsoft
|
365_apps microsoft_365 office_2019 office_2021 office_2024 sharepoint_server word
|
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-416
Use After Free
|
CVE-2026-45458
|
2026-06-12 00:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
560
|
- |
|
-
|
-
|
Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce identical challenges,…
New
|
CWE-345 CWE-1240
Insufficient Verification of Data Authenticity Use of a Cryptographic Primitive with a Risky Implementation
|
CVE-2026-46654
|
2026-06-12 00:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|